Skip to content
This repository has been archived by the owner on Sep 13, 2019. It is now read-only.

Anyone can view a user's information even without logging in #1

Closed
emadehsan opened this issue Mar 4, 2017 · 1 comment
Closed

Comments

@emadehsan
Copy link
Contributor

Anyone can view a user's information by providing his/her username.

Problem is here

Screen shot

Steps to generate
Do a POST request to http://SERVER_URL:PORT/chkuser with a parameter name. Set the value of name equal to the name of a valid HospitalRun user

@jkleinsc
Copy link
Member

jkleinsc commented Mar 8, 2017

Resolved by #2

@jkleinsc jkleinsc closed this as completed Mar 8, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants